BYOVD - Hive0163
BYOVD - Hive0163 is a blue team lab that falls under the Malware Analysis, Endpoint Forensics categories and will cover the following subjects: Ghidra, OpenSSL, Event Viewer, CyberChef, VirusTotal, Registry Explorer, IDA Pro, Python, Detect It Easy, PE-bear, pe-sieve, Execution, Persistence, Privilege Escalation, Stealth, Defense Impairment, Discovery, Collection, Command and Control, Exfiltration, Impact.
Learning Objectives
Correlate diverse forensic artifacts to reconstruct a multi-stage ransomware attack, synthesizing insights from BYOVD, custom packer, and anti-analysis techniques.
Categories: Malware Analysis, Endpoint Forensics.
MITRE ATT&CK Tactics: Execution, Persistence, Privilege Escalation, Stealth, Defense Impairment, Discovery, Collection, Command and Control, Exfiltration, Impact.
Tools: Ghidra, OpenSSL, Event Viewer, CyberChef, VirusTotal, Registry Explorer, IDA Pro, Python, Detect It Easy, PE-bear, pe-sieve.
Difficulty: hard.